Re: Remote root telnet exploit on Solaris 10 and 11

From: Tom Simes <simestd@netexpress.com>
Date: Mon Feb 12 2007 - 13:12:16 AKST

On Mon, 12 Feb 2007 12:08:24 -0900
"Shane Spencer" <shane@bogomip.com> wrote:
> Check out OpenSolaris, you will probably dig it ans ZFS :) I don't
> care much for telnet however.
>
> On 2/12/07, Damien Hull <dhull@digitaloverload.net> wrote:
> > I have two questions for you.
> >
> > 1. Why would you run Solaris?
> > 2. Why would you run telnet?

I am not advocating their use. Merely passing along what I consider to
be some potentially significant news in case admins on this list had
missed it from the usual sources. By the way, OpenSolaris is
apperently vulnerable as well:

http://www.lildude.co.uk/2007/02/telnetlogin-vuln-in-solaris-10opensolaris-disable-telnet-now/

The attched .pdf (complete with NSFW graphic) details the source code in
question.

Tom
 
======================================================================
   "Z-80 system stack overflow. Shut 'er down Scotty, the system's
         sucking mud" - Error message on TRS 80 Model-16B

Tom Simes simestd@netexpress.com
======================================================================

-- Binary/unsupported file stripped by Ecartis --
-- Type: application/pdf
-- File: 0day_was_the_case_that_they_gave_me.pdf

---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Mon Feb 12 13:12:42 2007

This archive was generated by hypermail 2.1.8 : Mon Feb 12 2007 - 13:12:43 AKST